mirror of
https://github.com/volatilityfoundation/volatility3.git
synced 2026-09-28 20:44:52 +02:00
Merge pull request #8 from volatilityfoundation/mhl-cmhive
move the hive name decision to _CMHIVE extension for hivelist (and ot…
This commit is contained in:
@@ -14,6 +14,7 @@ class WindowsKernelIntermedSymbols(intermed.IntermediateSymbolTable):
|
||||
self.set_type_class('_LIST_ENTRY', extensions._LIST_ENTRY)
|
||||
self.set_type_class('_EPROCESS', extensions._EPROCESS)
|
||||
self.set_type_class('_UNICODE_STRING', extensions._UNICODE_STRING)
|
||||
self.set_type_class('_CMHIVE', extensions._CMHIVE)
|
||||
|
||||
@classmethod
|
||||
def get_requirements(cls):
|
||||
|
||||
@@ -4,7 +4,7 @@ import string
|
||||
|
||||
from volatility.framework import interfaces
|
||||
from volatility.framework import objects
|
||||
|
||||
from volatility.framework import exceptions
|
||||
|
||||
# Keep these in a basic module, to prevent import cycles when symbol providers require them
|
||||
|
||||
@@ -13,6 +13,20 @@ class _ETHREAD(objects.Struct):
|
||||
"""Return the EPROCESS that owns this thread"""
|
||||
return self.ThreadsProcess.dereference(kernel_layer)
|
||||
|
||||
class _CMHIVE(objects.Struct):
|
||||
@property
|
||||
def name(self):
|
||||
"""Determine a name for the hive. Note that some attributes are
|
||||
unpredictably blank across different OS versions while others are populated,
|
||||
so we check all possibilities and take the first one that's not empty"""
|
||||
|
||||
for attr in ["FileFullPath", "FileUserName", "HiveRootPath"]:
|
||||
try:
|
||||
return getattr(self, attr).String
|
||||
except (AttributeError, exceptions.InvalidAddressException):
|
||||
pass
|
||||
|
||||
return None
|
||||
|
||||
class _UNICODE_STRING(objects.Struct):
|
||||
@property
|
||||
|
||||
@@ -21,13 +21,8 @@ class HiveList(plugins.PluginInterface):
|
||||
def _generator(self):
|
||||
for hive in self.list_hives():
|
||||
|
||||
try:
|
||||
FileFullPath = hive.FileFullPath.String
|
||||
except exceptions.InvalidAddressException:
|
||||
FileFullPath = ""
|
||||
|
||||
yield (0, (format_hints.Hex(hive.vol.offset),
|
||||
FileFullPath))
|
||||
hive.name or ""))
|
||||
|
||||
def list_hives(self):
|
||||
"""Lists all the hives in the primary layer"""
|
||||
|
||||
Reference in New Issue
Block a user